From 19 June 2026, every UK controller must operate a statutory data protection complaints procedure. Section 103 of the Data (Use and Access) Act 2025 inserts a new section 164A into the Data Protection Act 2018, giving individuals the right to complain directly to the organisation about how their personal data has been handled, and obliging the organisation to run a real process in response. The duties apply to complaints received on or after 19 June 2026, and the ICO’s guidance confirms there are no exemptions: every controller, whatever its size, is in scope. The right to complain to the ICO remains, but the design intent is controller first, regulator second.
What Section 164A Requires
The shape of the duty is straightforward. You must give people a clear and accessible way to complain, and accept complaints however they arrive, including by phone, on social media, or in person; a complaint does not need to use legal language or cite a statute to count. You must acknowledge the complaint within 30 days. You must then investigate without undue delay, make appropriate enquiries, keep the complainant informed, and tell them the outcome. Alongside this, the supplementary information that accompanies a subject access response now includes the right to complain to the controller as well as to the ICO, so your own DSAR cover letters will be pointing requesters at your own complaints process.
Why DSARs Will Dominate the Complaint Queue
How organisations handle subject access is historically the single issue the ICO receives the most complaints about. Section 164A moves the first round of those disputes in-house. The recurring complaints are predictable because they are the recurring failure modes of DSAR responses: the response was late, the response was incomplete, the search missed an obvious repository, or the redactions were wrong in one direction or the other. Every one of those is now something you must formally log, investigate, and answer on the record, and the record you create is exactly what the ICO will read if the complainant escalates.
Redaction Errors Are Now Complaints on the Record
Look at the redaction stage specifically and four failure modes carry complaint risk. Over-redaction: the requester says you hid their own data behind the third-party exemption, and you must justify each withholding. Under-redaction: someone else’s personal data went out in the bundle, which is a disclosure incident in its own right as well as a likely complaint from the affected person. Reversible redaction: a black box drawn over live text that any recipient can lift, which turns a response into an incident the moment someone tries copy and paste. And missed repositories, where the complaint is about what the bundle does not contain. The common thread is that a complaint response built from memory loses, and one built from records does not.
What a Defensible Response File Looks Like
The organisations that will find section 164A cheap are the ones whose DSAR process already produces its own evidence: a record of the search scope and why it was reasonable and proportionate, per-document redaction decisions with the exemption or balancing reasoning attached, an audit trail showing every file was actually reviewed by a person, and an export that physically removes what was redacted rather than covering it. With that file, a complaint response is largely quotation. Without it, every complaint is a reconstruction exercise on a 30-day acknowledgement clock.
How SafeRedact Fits
Files never leave your browser: documents are processed client-side, only extracted text is sent for AI detection, and no documents are stored on servers. Detection text is never used for training and is deleted within 30 days. DSAR mode lets you name the data subject whose information should be preserved while other individuals’ personal information is flagged for redaction across every file in the case. Every detection is reviewed by a human before anything is exported, and the output includes a processing summary and audit trail your privacy officer can stand behind if the ICO asks how the response was produced.
A Data Processing Agreement is available, and enterprise cases are priced per case, with the price set with you and shown before you download. See the enterprise overview or the enterprise FAQ for how cases run end to end.
Preparing Before the First Complaint
Three preparations pay for themselves. Update privacy notices and DSAR response templates so the complaints route is signposted, since the law now expects it. Decide who owns data protection complaints and how they are logged, because the 30-day acknowledgement duty starts on receipt through any channel. And tighten the DSAR record-keeping now, before a complaint tests it: the June deadline is about complaints received from that date, which means the responses you send today are the ones that will be complained about under the new regime.
Send DSAR Responses You Can Defend
Human-reviewed redaction with a processing summary and audit trail, so a complaint response is built from records, not memory.
Start Your EvaluationRelated Guides
Microsoft, Microsoft 365, SharePoint, Exchange Online, OneDrive, Teams, and Purview are trademarks of Microsoft Corporation. SafeRedact is not affiliated with or endorsed by Microsoft. This page is informational, not legal advice; the legislation, ICO guidance, and your counsel govern.